← dockestra.com

Privacy Policy

Effective date: 22 July 2026 · Applies to the Dockestra mobile app and web platform

1. Who we are

Dockestra ("Dockestra", "we", "us") provides an operations platform for yacht charter management companies ("operators"), delivered as a web application and as native iOS and Android apps. Each operator runs in its own isolated workspace (e.g. yourcompany.dockestra.com) with its own database and file storage.

For questions about this policy or to exercise your rights, contact privacy@dockestra.com.

2. Our two roles: controller and processor

Dockestra processes personal data in two distinct capacities:

  • As controller: for the account data of workspace users (operator staff and crew) and for the data needed to operate, secure, and bill the service.
  • As processor, on behalf of the operator: for personal data of the operator's passengers, guests, and business contacts that the operator enters into or syncs through the platform (for example the data appearing on crew & passenger manifests, boarding vouchers, and briefing cards). For this category, the charter operator is the data controller and Dockestra processes the data solely on the operator's instructions. Requests concerning this data should be directed to the operator; we will assist the operator in fulfilling them.

3. Data we process

3.1 Account data

  • Name, email address, role, and workspace/company affiliation.
  • Accounts are created by company administrators only. There is no self-registration; if you have an account, it was provisioned by your employer or contracting operator.

3.2 Operational content

  • Chat messages and threads, with server-side visibility levels (for example internal notes that crew accounts cannot see).
  • Uploaded photos, including EXIF metadata, which is retained for its evidentiary value in operational disputes (e.g. condition of a vessel at a point in time).
  • Deal and charter data, documents, and generated files (offers, manifests, vouchers, briefing cards).

3.3 Passenger and guest data (processed for the operator)

  • Passenger identity and travel details required for port-authority crew & passenger manifests.
  • Guest details and signatures on boarding vouchers, including recorded consent.
  • Operational details (e.g. dietary notes) included in crew briefing cards.

3.4 Device and security data

  • Push notification tokens, bound one-device-to-one-user.
  • Authentication tokens (JWT with refresh rotation).
  • Rate-limiting and security logs (e.g. IP address, timestamps of authentication events).

4. AI processing

When a user asks the Dockestra Assistant a question, the question text is routed via Anthropic's Claude for intent classification only: determining which report or query the question corresponds to. The answers themselves are computed by deterministic reports and live queries running in the operator's own workspace. Each AI call is metered and visible to workspace administrators on a cost dashboard.

5. Where data lives

  • Hosting on DigitalOcean infrastructure relevant to the EU.
  • Files in S3-compatible private object storage, accessed only via time-limited presigned URLs.
  • Nightly backups.
  • Per-company isolated databases: one operator's data is never pooled with another's.

6. Retention and deletion

  • Account data is retained while the account is active and removed or anonymized after the workspace relationship ends, subject to legal retention duties.
  • Operational content is retained under the operator's retention settings; workspace administrators have deletion tooling for content and accounts.
  • Manifest and voucher records may be subject to statutory maritime retention periods, which take precedence.

7. Your rights

Under the GDPR you have rights of access, rectification, and erasure, as well as rights to restriction, portability, and objection where applicable. To exercise them:

  • For workspace account data: contact privacy@dockestra.com.
  • For passenger/guest data: contact the charter operator you dealt with (the controller); we support the operator in responding.

You also have the right to lodge a complaint with your supervisory authority.

8. Data deletion requests

Workspace users may request deletion of their account by contacting their workspace administrator or privacy@dockestra.com. We will confirm completion once identity is verified, subject to the retention duties in section 6.

9. Changes to this policy

We will post any changes on this page and update the effective date above. Material changes will be notified to workspace administrators.

Home Terms of Service Support © 2026 Dockestra